Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationdata-exfiltration-methodunderground-data-leakinitial-access-method

Maze Ransomware Expanded Double-Extortion Tactics and Targeted Intrusions

Updated 9d agoFirst seen Jan 1, 20261 source

The Maze ransomware operation evolved from earlier exploit-kit activity associated with “ChaCha ransomware” into a prominent double-extortion threat that stole data before encrypting systems and then pressured victims by publishing stolen files on dedicated leak sites. Operators built a public reputation around naming victims, courting media attention, and using data exposure as leverage to increase the likelihood of ransom payments.

Maze infections were delivered through multiple channels, including spam campaigns impersonating government tax agencies and later more targeted compromises through Remote Desktop Protocol (RDP) access and network exploitation. Sophos reported that the malware used heavy obfuscation, anti-analysis checks, persistence mechanisms, system and network reconnaissance, HTTP POST data exfiltration, and file encryption based on RSA and ChaCha20, while also showing selective behavior such as adjusting demands for home versus corporate systems and easing pressure in some medical-sector cases during COVID-19.

Share:
Maze Ransomware Expanded Double-Extortion Tactics and Targeted Intrusions
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jan 1, 20266mo ago

Maze adopts selective behavior during the COVID-19 period

The report notes that during COVID-19, Maze at times avoided some medical targets and in certain cases reduced pressure, reflecting a selective operational approach.

Maze ransomware: extorting victims for 1 year and counting | SOPHOS

Maze shifts to targeted intrusions via RDP and network exploitation

According to Sophos, Maze later moved beyond broad delivery methods and conducted targeted intrusions using Remote Desktop Protocol access and network exploitation.

Maze ransomware: extorting victims for 1 year and counting | SOPHOS

Maze expands delivery to tax-themed spam campaigns

The report describes Maze being distributed through spam campaigns impersonating government tax agencies as part of its delivery evolution.

Maze ransomware: extorting victims for 1 year and counting | SOPHOS

Maze starts publicly leaking victim data on dedicated sites

Sophos reports that Maze distinguished itself by publicizing victims and operating dedicated victim and leak sites to increase extortion pressure through public exposure.

Maze ransomware: extorting victims for 1 year and counting | SOPHOS

Maze evolves into a public extortion-focused ransomware brand

The operation developed into Maze, a higher-profile ransomware brand that combined encryption with data theft and pressure tactics aimed at forcing victims to pay.

Maze ransomware: extorting victims for 1 year and counting | SOPHOS

Maze begins as ChaCha ransomware via exploit kits

Sophos says the operation started under the earlier 'ChaCha ransomware' label and was initially delivered through exploit kits before evolving into the Maze brand.

Maze ransomware: extorting victims for 1 year and counting | SOPHOS
SOURCE COVERAGE

Sources

1 reference tracked. Mallory keeps watching after this page renders.

1 SOURCESView all
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.